Junglewise Threat Intelligence

CVE-2023-29298: Adobe ColdFusion Improper Access Control Vulnerability

CVE-2023-29298 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2023-07-20

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is vulnerable to an improper access control flaw that allows an unauthenticated attacker to bypass security features. By exploiting this vulnerability, an attacker can gain unauthorized access to administration CFM and CFC endpoints without any user interaction.

Affected products

  • Adobe ColdFusion 2018 Update 16 and earlier
  • Adobe ColdFusion 2021 Update 6 and earlier
  • Adobe ColdFusion 2023 2023.0.0.330468 and earlier

Timeline

  • 2023-07-19: disclosed
  • 2023-07-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-07-20: other: Published to NVD

Related threats